This policy explains what personal information Doer collects, why we collect it, who we share it with, and what you can ask us to do about it. It covers the Doer website, the Doer mobile app, and the API behind both.
Doer is a marketplace: it exists to connect customers with local service providers, and some of what you enter is shown to the other side of that transaction by design. The section headed What other users can see sets out exactly where that line falls.
This document is published in English, and the English version is the one that governs.
1. Who we are
Doer is operated by COMPANY_NAME, registered in JURISDICTION at COMPANY_ADDRESS. For the purposes of the General Data Protection Regulation and of JURISDICTION data protection law, COMPANY_NAME is the data controller for the information described here.
Questions about this policy, and any request to exercise the rights described in section 10, should go to PRIVACY_EMAIL.
2. What we collect
We collect only what a booking marketplace needs to function. The table below lists every category of personal information held, and the reason it exists.
| Information | Why we hold it |
|---|---|
| Name and email address | To identify your account, sign you in, and address you in messages and notifications. Your email is also where one-time verification codes are sent. |
| Password | Stored only as a salted cryptographic hash. We cannot read it, and nobody at Doer can tell you what it is. |
| Phone number | Optional for customers, required when registering as a service provider, so that a customer and a provider can reach each other about a confirmed job. |
| Date of birth | Collected from service providers to confirm they are old enough to trade, and to derive an age band. The date itself is never shown to another user or returned by the API — see section 6. |
| Country, city and address | To match you with providers who cover your area, and to tell a provider where a job is. A provider's own city is shown publicly on their profile. |
| Location coordinates | Used to sort results by distance and to work out which providers are within range. Supplied either by your device, with your permission, or derived from an address you type. |
| Profile photo, company logo and portfolio images | Shown on your public profile. Provider profile photos are checked automatically for a single visible face before they are accepted. |
| Bookings and job descriptions | The service requested, the time, the address and anything you wrote about the job, shared with the provider you booked. |
| Messages | The content of conversations between a customer and a provider, retained so that both parties keep a record of what was agreed. |
| Ratings, reviews and recommendations | Published on the provider's profile under your display name, to help other customers choose. |
| Posts to the requests board | What you need done, where, and your budget. See section 6 for how much of this a signed-out visitor can see. |
| Subscription and payment records | Which plan you hold and when it renews. Card details are handled by Stripe and never reach our servers. |
| AI assistant conversations | When you use the AI search assistant, we record the question you asked, the assistant's reply, whether it was able to help, and the country and city the question related to. This is how we find out which services people want and cannot find. |
| Technical and diagnostic data | IP address, device and browser type, app version, and error reports, used to keep the service running, to apply rate limits, and to investigate faults. |
3. Where it comes from
- Directly from you, when you register, complete your profile, make a booking, post a request, send a message, or write a review.
- From your device, when you allow the app or the website to use your location.
- From Google or Apple, if you choose to sign in with one of them. We receive your name, your email address and the fact that the provider verified it. We never receive your password with either.
- From Stripe, which tells us that a subscription payment succeeded or failed. It does not send us your card details.
- Automatically, as you use the service: pages requested, errors encountered, and the diagnostic data described above.
4. Why we use it, and on what legal basis
| Purpose | Basis |
|---|---|
| Running your account, showing you providers, taking and managing bookings, and carrying messages between the two sides | Performance of the contract between you and us. |
| Sending one-time codes, booking confirmations, reminders and status changes | Performance of the contract. These are service messages, not marketing, and cannot be switched off while you hold an account with active bookings. |
| Taking subscription payments and keeping the records tax law requires | Performance of the contract, and compliance with a legal obligation. |
| Checking uploaded profile photos, limiting request rates, and detecting fraudulent or duplicate accounts | Our legitimate interest in keeping the marketplace safe and usable for everyone on it. |
| Recording which searches the assistant could and could not answer, in order to improve coverage | Our legitimate interest in understanding demand. These records are read in aggregate. |
| Showing advertising supplied by Google AdSense | Consent, where the law of your country requires it for the cookies involved; otherwise our legitimate interest in funding a free service. |
| Using your device location | Your consent, given to your browser or phone, and withdrawable there at any time. |
6. What other users can see
This is the part of the policy most specific to Doer, so it is set out precisely rather than in general terms.
- A service provider's profile is public. It shows their name, city, photo, services, prices, portfolio images, and the reviews customers have left. Providers choose to be listed, and this is what being listed means.
- A provider's date of birth is never shown to anyone and is never returned by our API, not even to the provider reading their own record. Only a band — such as 26 to 30 — is ever derived from it.
- A customer's identity is not public. When a booking or a review appears on our public activity feed, the customer's name is masked to a first name and an initial, and the address, the coordinates and the free text of the job are not included at all.
- A request posted to the public requests board shows a masked name, the category, the city and the budget. A signed-out visitor sees at most the first 120 characters of the description; the full text, and the ability to reply, require an account, and the truncation is done on our server so the rest is never sent to a browser that should not have it.
- When you book a provider, that provider sees your name, your contact details, the address of the job and what you wrote about it. That is the point of the booking.
- A provider replying to a posted request cannot see any other provider's reply, or how they priced it. The customer who posted it sees them all.
- A review you publish appears under your display name on the provider's profile, and may be quoted on our public activity feed with your name masked.
7. Advertising
We show advertising supplied by Google AdSense in order to keep Doer free to use. Google and its partners use cookies and similar identifiers to serve and measure those adverts, and in some cases to personalise them based on your previous visits to this and other sites.
You can review and change what Google does with that data at google.com/settings/ads, and can opt out of personalised advertising by third-party vendors at aboutads.info/choices. Where the law of your country requires consent for advertising cookies, we ask for it before any are set, and you can change your answer at any time.
We do not give advertisers your name, your email address, your phone number, your address, your messages or your bookings.
9. How long we keep it
- Account information is kept while your account is open, and for ACCOUNT_RETENTION_PERIOD after you close it, so that a dispute about a completed job can still be resolved.
- Bookings, invoices and payment records are kept for FINANCIAL_RETENTION_PERIOD, because tax and accounting law requires it.
- Messages are kept for as long as both accounts exist, then deleted with them.
- Published reviews remain on a provider's profile after your account closes, but are detached from your identity.
- Assistant conversation records are kept for ANALYTICS_RETENTION_PERIOD and are read in aggregate. After that period they are deleted.
- Diagnostic logs are kept for LOG_RETENTION_PERIOD.
10. Your rights
Depending on where you live, and in every case under the GDPR and under JURISDICTION data protection law, you have the right to:
- Ask for a copy of the personal information we hold about you.
- Have inaccurate information corrected. Most of it you can correct yourself, from your profile.
- Ask us to delete your account and the information attached to it, subject to the records we are legally required to keep.
- Object to processing we carry out on the basis of legitimate interests, and to withdraw any consent you have given, including location and advertising consent.
- Ask us to restrict what we do with your information while a dispute about it is resolved.
- Receive the information you gave us in a portable, machine-readable form.
- Complain to your data protection authority if you think we have got this wrong. We would rather you told us first, at PRIVACY_EMAIL, so that we can put it right.
We respond to requests within 30 days. We will ask you to confirm your identity first, because handing your data to somebody who merely claims to be you would be the worst possible outcome of a policy like this one.
11. Children
Doer is not for children. You must be at least 18 to hold an account, whether as a customer or as a service provider. If we learn that an account belongs to a child, we close it and delete the information held under it. If you believe a child has registered, tell us at PRIVACY_EMAIL.
12. How we protect it
Traffic between your device and our servers is encrypted in transit. Passwords are stored only as salted hashes. Access to production data is restricted to the people who need it to operate the service. Uploaded files are validated before they are accepted, and administrative functions are gated by role.
No service can promise that a breach is impossible. If one occurs and it puts your rights at risk, we will tell you and the relevant authority within the time the law allows.
13. Where your information is held
Our servers are located in HOSTING_REGION. Some of the processors named in section 5 operate outside that region, which means your information may be transferred internationally. Where it is, we rely on the European Commission's standard contractual clauses, or on an adequacy decision covering the country concerned.
14. Changes to this policy
When this policy changes, we update the date at the top of the page. If a change materially affects your rights, we will tell you by email or in the app before it takes effect, rather than relying on you to notice.
15. Contact us
Write to PRIVACY_EMAIL, or to COMPANY_NAME, COMPANY_ADDRESS. For anything that is not about privacy, the contact page lists the better address to use.